Galaxy Research says it has confirmed with high confidence that 1,719 BTC, worth roughly $111 million, has been stolen through the ongoing Coldcard hardware-wallet exploit, and that total losses could ultimately swell past $130 million as the investigation continues.

The firm's analysis found the confirmed thefts span more than 25 distinct attack patterns across three separate waves, evidence Galaxy says points to multiple threat actors independently exploiting the same flaw rather than a single coordinated attacker.

Coldcard Hack Losses Could Hit $130M, Galaxy Research Says
Image via @WuBlockchain on X

A Firmware Bug From 2021

The root cause traces back to a March 2021 firmware integration error that mistakenly routed seed generation on affected devices to a deterministic software pseudorandom number generator instead of the hardware-based RNG built into the Coldcard's STM32 chip. That flaw appears limited to Coldcard Mk3, Mk4, Mk5 and Q devices running firmware released after March 17, 2021, meaning any wallet seed generated on a vulnerable device in the years since could theoretically have been predictable to an attacker who reverse-engineered the bug.

Funds Sitting Still, For Now

Notably, Galaxy's researchers found that the majority of stolen funds remain unspent on-chain, with attackers moving the bitcoin into new wallets but not yet converting or dispersing it through typical laundering channels — a pattern that could still give investigators and exchanges a window to flag the tainted coins before they're cashed out. The incident adds to a rough stretch for hardware-wallet security generally, following on from earlier reporting that pegged victim losses at a median of 1 BTC each as the theft total first crossed $111 million.

Related: Coldcard Hack Victims Report Median 1 BTC Loss as Theft Tops $111M